Processing basis and records
Before an agent touches personal data we document what data it processes, on what legal basis, for how long, and who can read the logs. That belongs in the scoping document, not in a review three weeks before launch.
Controls mapped to the risks they actually address. No badges we have not earned, and no claims we cannot show you the evidence for.
Neuro is not certified against ISO 27001 or SOC 2. We say so plainly rather than displaying badges we do not hold. What we can show you is the access model, the audit trail and the retention policy for every agent we have shipped, and we will walk your security team through them before any contract.
An agent reads records the requester was never allowed to see.
The agent inherits the requesting user’s permissions at query time rather than holding a superset of its own. Documents outside that scope are never retrieved, so they cannot appear in an answer.
Confidential documents end up training a third-party model.
We only use model providers under agreements that exclude your data from training, and we process inside the European Union. The provider list and its terms are part of the engagement documentation.
An agent changes a customer record and nobody can explain why.
Every run logs the input, the documents retrieved, the tools called and the output. A decision can be replayed months later, which is what makes an audit a walkthrough rather than a rewrite.
A wrong action propagates before anyone notices.
Reads are free. Drafts and internal notes apply automatically and are reversible. Anything customer-visible or financial waits for a named human until the test set justifies otherwise.
Conversation history accumulates indefinitely by default.
Retention is a design decision made during scoping, not a default. We keep the shortest window the process tolerates, separate prompts from personal data where possible, and treat deletion as a tested operation.
A model change silently degrades quality.
The business test set runs on every model, prompt or retrieval change. A drop in score blocks the release. Nothing reaches production on the strength of a demo.
These four questions are cheaper to answer before a system is connected to real records than after.
Before an agent touches personal data we document what data it processes, on what legal basis, for how long, and who can read the logs. That belongs in the scoping document, not in a review three weeks before launch.
We classify each agent against the Act’s risk tiers and record the reasoning. Users are told when they are talking to an agent, and every agent has a documented human escalation path.
Each agent runs under its own service account with its own scopes, never a borrowed human login. That makes access reviewable and revocation a single step.
Inference and storage happen with providers inside the European Union. The hosting decision is made explicitly at scoping and written into the engagement.
We would rather answer hard questions at scoping than at launch. Send your questionnaire and we will work through it.
Book a diagnostic